Files
fzf.vim/autoload
Junegunn Choi d538da05b6 Do not run arbitrary Ex commands from tag addresses
A tags file can come from an untrusted source, and its address field can hold
any Ex command, which :Tags, :BTags and their CTRL-O Show callback ran as is.

- Take only a line number or a search pattern, chained with ';' for
  '--excmd=combine' and cut at the ';"' terminator as Vim's find_extra() does.
  A pattern left unterminated runs to the end of the line, taking any '|' or
  ';' with it, so it cannot chain a command
- Run the address in a sandbox, as builtin tag jumps do since Vim 6.0

Close #1626
2026-09-27 20:52:29 +09:00
..